Security researchers at AIR Security disclosed a vulnerability last week that hit four major AI coding agents at once, Anthropic's Claude Code, OpenAI's Codex, Microsoft's GitHub Copilot, and Google's Gemini CLI. Two have been patched. Two have not. The flaw, named Plugin4Shell, doesn't target the AI models themselves. It targets the plugin marketplaces these agents pull from, and it requires nothing from the person using the tool, no click, no approval, no mistake on their part at all.

4
Major AI coding agents affected: Claude Code, Codex, GitHub Copilot, and Gemini CLI
2
Still without a fix as of this writing, Copilot and Gemini CLI
0
Clicks, approvals, or mistakes required from the user for the attack to succeed

What This Actually Lets an Attacker Do

Coding agents can install plugins, skills, and extensions from community marketplaces to extend what they can do. To keep that safe, developers rely on a practice called SHA pinning: once a plugin has been reviewed and approved, it gets locked to one specific, exact version of the code, identified by a 40-character fingerprint. The promise that pin is supposed to make is simple: This agent will only ever run the exact code someone already checked and approved, nothing else, ever, unless a human deliberately reviews and approves a new version.

In Plain Terms

Think of SHA pinning as a wristband from a reviewed, trusted vendor. The agent is told: Only accept deliveries wearing this exact wristband. Plugin4Shell lets an attacker manufacture a fake wristband that looks identical to the real one, then swap out what's inside the box. The agent checks the wristband, sees it matches, and lets the package through without ever opening it to compare contents against what was actually reviewed.

Here's the part that makes this dangerous rather than just theoretically interesting: Claude Code and Codex both check for plugin updates automatically, in the background, on their own schedule. Nobody has to click update. Nobody has to approve anything. The agent periodically checks its marketplace for a new version carrying that same wristband, and if an attacker has already staged the swap, the agent pulls down the malicious version and starts running it, unattended, the next time that background check happens. The user finds out nothing changed. Their agent just quietly started running code someone else wrote, with no prompt, no warning, and no record that anyone approved it.

Once that malicious code is running, it inherits whatever access the coding agent itself already has. For a coding agent, that's typically substantial: read and write access to your codebase, visibility into environment variables and stored credentials, and in many setups, the ability to execute commands directly in development or even production environments. This isn't an attacker guessing a password or tricking someone into opening an attachment. It's an attacker getting a developer-level foothold inside your systems through a routine, automatic process nobody was watching.

Which Tools Are Fixed, and Which Aren't

AIR Security reported the flaw to all four vendors in June, giving each roughly three months before public disclosure on September 17. Anthropic patched Claude Code in version 2.1.179. OpenAI patched Codex in version 0.146.0. If you run either tool, updating to those versions or later closes the hole.

Google took a different path entirely: rather than fix Gemini CLI, it deprecated the product outright, meaning every existing installation stays vulnerable indefinitely, with Google's guidance being to migrate to its newer Antigravity agent instead, which doesn't use the same plugin marketplace architecture and isn't exposed to this particular flaw. Microsoft had not shipped a fix for Copilot as of the most recent reporting. A GitHub spokesperson has disputed that GitHub Copilot specifically is affected by Plugin4Shell attacks, a claim that sits in tension with earlier reporting naming Copilot among the affected agents, and one worth watching for clarification rather than treating as settled either way.

Two Related VariantsClaude Code, Codex, and GitHub Copilot share one version of the flaw, tied to how git handles branch names that happen to match a commit hash. Gemini CLI is exposed through a separate mechanism in how it fetches and verifies pinned commits. The technical path differs, but the outcome for a user is identical either way.

Why This Is Being Called a First

AIR Security describes Plugin4Shell as a first-of-its-kind AI supply-chain attack, and the distinction matters. Most AI security incidents this year have targeted the models themselves, tricking them into misbehaving through clever prompts, or the accounts and credentials around them. This one targets the trust relationship between an agent and the marketplace it pulls plugins from, a layer most security teams aren't yet monitoring closely, if at all. Because a single compromised marketplace entry can reach every agent that installed it, the potential blast radius is far wider than one company's misconfigured account.

What This Means If Your Team Uses These Tools

Sources: AI Pulse · Where This Breaks · workplaceai.ai. Plugin4Shell disclosure, technical details, and vendor patch status: AIR Security's disclosure, The Register, Help Net Security, and CyberSecurityNews, September 17-18, 2026. The GitHub Copilot dispute: The Register. Every technical detail above is attributed to its original reporting; none is a WorkplaceAI study.